GKE Secret get or list with Suspicious User Agent
Description
Detects successful GKE secret get or list operations where the user agent matches scripting runtimes, minimal HTTP clients, or offensive-distribution fingerprints rather than typical kubectl or controller traffic.
Query · kuery
data_stream.dataset:gcp.audit and service.name:"k8s.io" and event.outcome:success and
event.action:("io.k8s.core.v1.secrets.list" or "io.k8s.core.v1.secrets.get") and user_agent.original:(
curl* or python* or Python* or wget* or Go-http* or perl* or java* or node* or php* or *distrib#kali* or *kali-amd64* or
*kali-arm64* or Bun* or axios* or undici*
)
Known false positives
- Approved scripts, CI jobs, or penetration tests may use generic HTTP clients. Validate tickets and identity scope before treating as compromise.
Analyst notes
Investigating GKE Secret get or list with Suspicious User Agent
Review user.email, user_agent.original, targeted secret resource, and source.ip.
Investigation steps
- Confirm whether the identity should access secrets with this client fingerprint.
- Pivot on source IP for other API bursts, exec, or RBAC changes.
False positives
- Internal automation using generic libraries; exclude stable service accounts after review.
Setup
The GCP Fleet integration with GKE audit logs enabled is required to be compatible with this rule.